DPIA vs FRIA: Key Differences, Legal Requirements, and When You Need Both

A practical guide for organisations deploying AI in Europe, the UK, Ireland, and the US.

Published: May 2026  |  5–8 min read  |  Keywords: DPIA, FRIA, GDPR Art. 35, AI Act Art. 27, Fundamental Rights Impact Assessment, Data Protection Impact Assessment, High-Risk AI, EU AI Act Compliance, AI Governance, Responsible AI

 

The EU AI Act is now in force. For organisations deploying artificial intelligence, this means a new legal obligation sits alongside the familiar GDPR: the Fundamental Rights Impact Assessment (FRIA) under Article 27. Many compliance teams assume their existing Data Protection Impact Assessment (DPIA) covers both. It does not. When high-risk AI processes personal data, both assessments are legally required — simultaneously.

This post explains the difference, when each applies, and how to run them together efficiently.

Executive Summary

Organisations deploying AI in Europe increasingly need to assess both data protection risks and broader fundamental rights impacts. While a Data Protection Impact Assessment (DPIA) under GDPR Article 35 focuses on risks arising from personal data processing, a Fundamental Rights Impact Assessment (FRIA) under Article 27 of the EU AI Act evaluates the wider impact of high-risk AI systems on fundamental rights such as equality, non-discrimination, human dignity, and access to justice.

Many organisations assume that an existing DPIA satisfies AI Act requirements. In most cases, it does not. Where a high-risk AI system listed in Annex III of the EU AI Act also processes personal data at high risk, both assessments are typically required.

This guide explains the differences between DPIAs and FRIAs, when each applies, and how organisations can efficiently manage both obligations within a unified AI governance framework.

Key Definitions

A Data Protection Impact Assessment (DPIA) is a GDPR requirement under Article 35 used to identify, assess, and mitigate risks to individuals arising from high-risk personal data processing activities.

A Fundamental Rights Impact Assessment (FRIA) is an assessment required under Article 27 of the EU AI Act for deployers of certain high-risk AI systems. It evaluates the impact of AI systems on fundamental rights beyond privacy and data protection.

Annex III of the EU AI Act identifies categories of AI systems considered high-risk, including systems used in employment, education, biometric identification, law enforcement, migration, credit scoring, and access to essential services.

Under the EU AI Act, a deployer is the organisation or individual using an AI system under its authority, except where the AI system is used in a personal, non-professional context.

AI governance refers to the policies, controls, assessments, oversight mechanisms, and accountability structures used to ensure AI systems are deployed responsibly, legally, and ethically.

1. The DPIA — GDPR Article 35

What it is: A structured risk assessment of personal data processing operations that are likely to result in high risk to individuals’ rights and freedoms.

When it is required:

  • Systematic profiling or automated decision-making with significant effects on individuals
  • Large-scale processing of special category data (health, biometric, genetic, etc.)
  • Systematic monitoring of publicly accessible areas
  • Any processing flagged as high-risk by your national Data Protection Authority (DPA)

What it must cover (Art. 35(7) GDPR):

  • Description of the processing and its purpose
  • Assessment of necessity and proportionality
  • Risk assessment to data subjects’ rights and freedoms
  • Measures to address identified risks

Who owns it: The Data Controller. The DPO must be consulted. If high residual risk remains, prior consultation with the DPA (Art. 36 GDPR) is mandatory before processing begins.

Applies to AI? Yes — any AI system that processes personal data at high risk triggers a DPIA independently of the AI Act.

2. The FRIA — EU AI Act Article 27

What it is: An impact assessment of deploying a high-risk AI system on the full spectrum of EU fundamental rights — going well beyond privacy and data protection.

When it is required: When deploying an AI system listed in Annex III of the EU AI Act, including:

  • Biometric identification and categorisation systems
  • AI in employment, recruitment, and worker management
  • AI in education and vocational training
  • Credit scoring and access to essential services
  • Law enforcement, migration, border control
  • Administration of justice and democratic processes

What it must cover (beyond privacy):Human dignity and non-discrimination (algorithmic bias)

  • Equality and vulnerable group impacts (children, minorities, persons with disabilities)
  • Freedom of expression, assembly, and access to justice
  • Workers’ rights in AI-assisted employment decisions

Who owns it: The Deployer of the AI system — not the provider/developer. Public-sector deployers must register a FRIA summary in the EU AI Act database. Private-sector deployers maintain it internally.

Key distinction: The FRIA covers group and societal impacts, not just individual data subjects — a broader lens than GDPR allows.

3. Side-by-Side: DPIA vs FRIA

Dimension DPIA — GDPR Art. 35 FRIA — AI Act Art. 27
Legal Basis GDPR Article 35 EU AI Act Article 27 + Annex III
Owned by Data Controller Deployer of the AI system
Focus Personal data risks to individuals Fundamental rights impacts (broader: dignity, equality, access to justice, privacy, and more)
Trigger High-risk data processing (profiling, sensitive data, systematic monitoring) Deploying a high-risk AI system listed in Annex III
Timing Before processing begins Before deployment
Public disclosure Internal — DPA consultation if risk remains high Public sector: EU database registration. Private sector: internal record
Fines (max) €10M or 2% global turnover €15M or 3% global turnover
Overlap zone Both apply when an Annex III AI system also processes personal data at high risk Both apply when an Annex III AI system also processes personal data at high risk

4. When You Need Both

Both apply when an Annex III high-risk AI system also processes personal data at high risk to individuals. In practice, most Annex III systems do exactly this. Examples:

  • Recruitment AI: Annex III trigger (employment AI) + GDPR trigger (automated decisions affecting employment prospects)
  • Credit scoring AI: Annex III trigger (access to financial services) + GDPR trigger (large-scale profiling)
  • Biometric workplace system: Annex III trigger + GDPR trigger (sensitive biometric data processing)
⚠️ Critical: A DPIA Does Not Replace a FRIA
The FRIA extends to rights entirely outside GDPR’s scope (dignity, equality, access to justice, freedom of expression). Each assessment is a separate legal obligation. They can share underlying documentation — but each must be completed and maintained independently.

5. Jurisdictional Quick Reference

EU

Both GDPR (DPIA) and the EU AI Act (FRIA) apply when their respective triggers are met. AI Act Annex III obligations for deployers apply from August 2026.

Ireland

The Data Protection Commission (DPC) oversees DPIA compliance. Irish-based multinationals are DPC-regulated. An AI supervisory authority is being designated — monitor updates from the DPC and AI Office.

United Kingdom

UK GDPR mirrors GDPR DPIA obligations (ICO oversight). The UK has not adopted the EU AI Act but sector regulators (ICO, FCA, Ofcom) are developing AI-specific guidance. UK entities with EU operations remain subject to the FRIA when deploying Annex III systems in the EU.

United States

No federal DPIA or FRIA equivalent exists, but NIST AI RMF and state-level AI laws (Colorado, Connecticut, Texas) increasingly require impact assessments. US multinationals with EU operations must comply with both the GDPR and the AI Act obligations for their European activities.

6. Next Steps: your action plan

  • Classify your AI systems: Check every AI tool against Annex III. If it qualifies as high-risk and processes personal data, you need both a DPIA and an FRIA.
  • Review existing DPIAs: AI deployments may now require a FRIA in addition to a DPIA already in place.
  • Assign ownership: DPO leads the DPIA; a named AI governance lead should own the FRIA. Collaboration is essential.
  • Build an integrated template That Shares the system description, data maps, and risk register across both assessments to avoid duplication.
  • Revisit vendor contracts: If you deploy third-party AI, your contract must require the provider to share sufficient technical information to complete your FRIA.
  • Set review triggers: Material changes to the AI system, new datasets, or regulatory updates should trigger simultaneous reviews of both assessments.
  • Start now: FRIA obligations for Annex III deployers take effect in August 2026. Readiness assessments should begin immediately.
Key Takeaway
DPIA and FRIA are complementary, not interchangeable. The DPIA protects personal data rights under GDPR. The FRIA protects the full spectrum of fundamental rights under the EU AI Act. Together, they form the foundation of responsible AI governance in Europe — and the benchmark other jurisdictions are moving towards.

 

 

Frequently Asked Questions

No. A DPIA and a FRIA are separate legal obligations. While they may share supporting documentation, each addresses different risks and must be completed independently when required.

If you deploy a high-risk AI system under Annex III of the EU AI Act and the system processes personal data in a manner that triggers GDPR Article 35, both assessments will generally be required.

The Data Controller is responsible for ensuring a DPIA is completed. The Data Protection Officer (DPO) should be consulted where applicable.

The deployer of the AI system is responsible for completing and maintaining the FRIA.

For deployers of Annex III high-risk AI systems, FRIA obligations become applicable from August 2026 under the EU AI Act implementation timeline.

The UK has not adopted the EU AI Act. However, organisations operating in the EU may still be required to complete a FRIA for their EU activities.

Organisations can use a shared methodology, common system documentation, and a unified risk register. However, the DPIA and FRIA remain separate legal requirements and should be documented independently.

Failure to comply with applicable EU AI Act obligations may result in regulatory enforcement measures and administrative fines, depending on the nature of the breach.

How Can Symmetry Compliance Help?

At Symmetry Compliance, we support organisations across Ireland, the EU, the UK, and the US in navigating the intersection of data protection law and AI governance. Whether you are completing your first DPIA, preparing for AI Act obligations, or building an integrated governance programme, our team brings practical, regulator-ready expertise.

DPIA Support

  • DPIA screening and scoping
  • End-to-end DPIA delivery
  • DPO advisory support
  • DPA consultation support

FRIA Support

  • Annex III classification reviews
  • FRIA design and delivery
  • Fundamental rights impact analysis
  • EU AI Act compliance support

Integrated AI Governance

  • Combined DPIA and FRIA frameworks
  • AI governance policies and templates
  • Training and awareness programmes
  • Ongoing compliance monitoring

 

📩 Get in Touch
If you would like to discuss your organisation’s DPIA or FRIA obligations, or explore how Symmetry Compliance can support your AI governance programme, contact our team at www.symmetrycompliance.ie. We work with organisations of all sizes — from scaling technology companies to established financial institutions and public bodies.

Official References

GDPR Article 35: https://gdpr-info.eu/art-35-gdpr/

EU AI Act Article 27: https://artificialintelligenceact.eu/article/27/

EU AI Act Implementation Documents: https://artificialintelligenceact.eu/implementation-documents/

Digital Policy Alert — AI Act Art. 27 Analysis: https://clairk.digitalpolicyalert.org/chat-demo?d=738&t=0

EDPB Guidelines on DPIA (WP 248 rev.01): https://edpb.europa.eu/our-work-tools/our-documents/wp29-guidelines/guidelines-dpia-wp248_en

ICO AI & Data Protection Guidance (UK): https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/

NIST AI Risk Management Framework: https://www.nist.gov/artificial-intelligence/ai-risk-management-framework

This post is for informational purposes only and does not constitute legal advice. © Symmetry Compliance 2025.

2026-07-01T22:52:36+01:00June 4th, 2026|AI, AI Act, Data Governance, Data Protection, DPIA, DPO, GDPR, Personal data, Privacy|